Skip to main content

Device Access Map

The Access Map is a tab on the device page that shows what each AI agent on one machine can reach. Every AI agent the scan agent found (Claude Code, Cursor, Codex, and so on) is drawn with the MCP servers and skills it has configured, and each of those carries its AI risk, its guard result, and whether a policy rule enforces it. A skill that comes back critical stands out on the map before anyone runs it.

Beta

The Access Map is a beta feature. It appears only when the Device Access Map beta flag is on for your organization; ask your Willow contact to turn it on. See Beta Features.

Open the Access Map​

  1. Open AI Discovery and select the Devices tab. See The AI Discovery dashboard.
  2. Open a device, then select the Access Map tab.

From a device's side panel, the Access map icon in its header opens the same tab directly.

The map reflects the device's most recent scan. Until the scan agent reports an AI agent on the device, the tab reads No AI agents discovered on this device.

What it shows​

Each AI agent on the device gets its own group (a base camp on the map, a card in the table). For each agent you see:

  • The account it is signed in with, when the scan agent reports one. An account outside your company's email domain is flagged as a Personal account, since an agent signed in with a personal email works outside your organization's controls.
  • Its MCP servers and skills, sorted with the riskiest first.
  • How many need attention and how many are enforced by a policy rule.

Each MCP server and skill carries three signals:

SignalWhat it tells you
AI riskThe AI risk band and 0–10 score from Willow's risk assessment, for example High · 7/10, or Not assessed. See How Willow assesses risk.
GuardsThe result of the last Guard Check: Passed, Guard warning, Blocked by guard, or Not checked.
EnforcementWhat a policy rule does with it: Blocked, Warn, Force-managed, Managed, Allowed, or no policy.

A capability needs attention when its AI risk is medium, high, or critical, or its guard check warned or blocked. It is critical when its AI risk is critical or a guard blocked it. Capabilities you already manage through Willow don't count as needing attention.

The toolbar above the map controls what is shown:

  • Needs attention or All. The tab opens on Needs attention when anything on the device needs it, and on All otherwise.
  • MCPs and Skills toggles show or hide each kind.
  • The search box highlights matching agents, MCP servers, and skills on the map, and filters the rows in the table.
  • Map or Table switches the view.

The map view​

The map draws the device as an isometric landscape: each AI agent is a base camp, and each MCP server and skill it reaches is a block on that camp, with pins for AI risk, guard results, and enforcement.

The overlay picker at the top left colors the blocks by one signal at a time, and the legend explains the colors:

OverlayColors blocks by
AttentionCritical, Needs attention, Managed, or No issues.
AI riskCritical, High, Medium, Low, or Not assessed.
GuardsBlocked by guard, Guard warning, Passed, or Not checked.
EnforcementBlocked, Warn, Force-managed, Managed, Allowed, or No policy.

Hover a block to see its AI risk, guard result, and enforcement. Click a camp to fly to it, and click it again to show every camp.

ControlAction
Drag, or the arrow keysPan
Scroll or pinch, or + / −Zoom
Shift + drag, or right-dragOrbit (3D)
2 / 3Switch between 2D and 3D
Q / ERotate 90°
FFit everything
EscClear focus or exit fullscreen

The table view​

The table lists the same data as one card per AI agent, with its signed-in account, its MCP server and skill counts, and the capabilities grouped under MCP Servers and Skills. Rows that need attention are marked amber, and critical ones red.

Open a capability​

Select any MCP server or skill, on the map or in the table, to open its detail panel: its configuration, the file it was found in, its guard check, and its full AI risk assessment with the reasoning behind the score. From there you can Add to Policy Rule, or Add to Gateway to bring it under management.